
A subject of financial monitoring (SFM) — the statutory term for a reporting entity — is an organisation or individual listed in paragraph 1 of Article 3 of Law of the Republic of Kazakhstan No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction” (Law No. 191-IV, the AML/CFT/CPF Law), on which the Law imposes duties to detect and report transactions in money and other property to the Agency of the Republic of Kazakhstan for Financial Monitoring (AFM), the authorised body for financial monitoring (Kazakhstan’s financial intelligence unit). In 2026 the list has 27 items, three of which have been deleted, and it covers banks, exchanges, insurers, pension funds, professional securities-market participants, notaries, advocates and legal consultants, accounting and audit firms, gambling operators, postal money-transfer operators, microfinance (including pawnshops) and payment organisations, unlicensed lessors, dealers in precious metals and jewellery, real-estate agents, the Social Health Insurance Fund, participants of the Astana International Financial Centre (AIFC), the State Corporation, mobile operators and — since 1 May 2026 — five categories of digital-asset operators and issuers. The duties of every SFM fall into six blocks: customer due diligence (Articles 5–9); detection of threshold transactions at fixed amounts from KZT 1,000,000 to KZT 500,000,000 and of suspicious transactions with no threshold (Article 4); reports to the AFM through the personal account on Form FM-1 within fixed deadlines (Articles 10, 10-1 and 13); internal control rules (ICR) with a responsible officer and trained staff (Article 11); freezing of transactions and refusal of service to listed persons (Articles 12, 12-1 and 13); and record-keeping for at least five years (Article 11). For breaches, Article 214 of the Code of Administrative Offences (CAO) provides fines from 30 to 1,800 monthly calculation indices (MCI) — at the 2026 MCI of KZT 4,325 that is KZT 129,750 to KZT 7,785,000 — with suspension of a licence or a ban on activity for up to three years for a third breach within a year.
Key facts. First: Law No. 191-IV applies in the wording in force as at 13 August 2026; the central reform is Law No. 219-VIII of 19 September 2025, in force since 20 November 2025, which renamed the Law, introduced the concept of a customer’s suspicious activity (two or more suspicious transactions) with its own three-working-day reporting deadline (Article 10-1) and created preventive control by the AFM without a visit to the entity (Article 14-1). Second: since 1 May 2026, under Law No. 259-VIII of 16 January 2026, the list includes operators of exchange of unsecured digital assets, operators of digital financial asset platforms, operators of digital-asset trading platforms, issuers of digital financial assets and participants of the National Bank’s special regulatory regime (sub-paragraphs 23)–27) of paragraph 1 of Article 3). Third: registration in the personal account on the AFM portal is mandatory for every SFM whether or not it has any reportable transactions (paragraph 2-1 of Article 10; Rules for the Personal Account approved by AFM Order No. 18 of 8 December 2025). Fourth: Article 214 of the CAO applies in the wording of Law No. 247-VIII of 30 December 2025 (in force since 2 March 2026) and contains 19 offences — from breach of record-keeping rules (30–280 MCI) to a third breach within a year (200–1,800 MCI with suspension of a licence for up to six months, suspension of activity for up to three months or a ban on activity for up to three years). Fifth: according to the AFM Chairman’s report to the President on 12 January 2026, in 2025 the financial sector terminated business relationships with 2,000 companies and 56,000 individuals on suspicion of laundering; the Eurasian Group (EAG) upgraded Kazakhstan’s ratings on four FATF Recommendations in May 2026, and Kazakhstan is not on the FATF list of jurisdictions under increased monitoring of 19 June 2026.
The duties of a subject of financial monitoring form a system of six interlocking requirements of Law No. 191-IV, most of which carry their own offence in Article 214 of the CAO. The table below maps the duties, provisions, deadlines and fines for a medium-sized enterprise (the third scale of Article 214 — medium-sized business entities); each row is developed in the sections that follow.
|
Duty of the SFM |
Provision of Law No. 191-IV |
Deadline |
Fine for a medium-sized enterprise (Article 214 CAO) |
|
Register in the AFM personal account; for legal consultants, lessors, jewellers and real-estate agents — file a notification of commencement of activity |
Paragraph 2-1 of Article 10; paragraph 3 of Article 3 |
Notification — before starting activity; no statutory deadline for registration in the account |
No separate offence in Article 214; activity without notification — Article 463 CAO (40 MCI for a medium-sized enterprise) |
|
Conduct due diligence on the customer, its representative and beneficial owner |
Articles 5–9 |
Before establishing a business relationship; update within 15 working days once doubts arise |
Part 8 — 280 MCI (KZT 1,211,000) |
|
Report a threshold transaction |
Paragraph 1 of Article 4; paragraph 2 of Article 10 |
No later than the working day following the transaction |
Parts 12–13 — 260–300 MCI |
|
Report a suspicious transaction |
Paragraph 3 of Article 4; paragraph 2 of Article 13 |
Before the transaction; if recognised afterwards — within 24 hours |
Parts 2–3 — 290–330 MCI |
|
Report a customer’s suspicious activity |
Article 10-1 |
No later than three working days after recognition |
No separate offence in Article 214; the transactions making it up — parts 2–3 |
|
Answer an AFM request |
Paragraph 3-1 of Article 10 |
Three working days; for the analysis of a suspicious transaction — no later than the working day on which the request is received |
Parts 4–5 — 280–300 MCI |
|
Adopt ICR, appoint a responsible officer, train and test staff |
Article 11; AFM Orders No. 4 and No. 6 of August 2021 |
No express statutory deadline — in practice before the first transaction; the test — before taking up the function |
Parts 11, 15, 16 — 210–345 MCI |
|
Freeze transactions of persons on the terrorist-financing and proliferation-financing lists |
Articles 12, 12-1; paragraph 1-1 of Article 13 |
Within 24 hours of publication of the list |
Part 9 — 330 MCI (KZT 1,427,250) |
|
Refuse service where due diligence is impossible; report the refusal |
Paragraph 1 of Article 13 |
Report — no later than the next working day |
Part 10 — 280 MCI |
|
Keep records and never disclose that a report has been filed |
Paragraphs 4–5 of Article 11 |
Five years from the end of the relationship or the transaction |
Parts 1 and 17 — 210–330 MCI |
Author’s assessment: the defining feature of Kazakhstan’s regime is dual-track reporting. Unlike many jurisdictions, where mandatory reporting is built around suspicious transactions and, at most, large cash transactions, Law No. 191-IV requires reports of threshold transactions across a wide range of transaction types — cash and non-cash alike — regardless of any suspicion, and that creates two separate grounds for a penalty: for a missed threshold transaction (parts 12–13 of Article 214 CAO) and for a missed suspicious one (parts 2–3). For a company that has only just acquired SFM status this means that, even with no doubtful customers at all, the flow of mandatory reports to the AFM begins with the first large payment. Which businesses in Kazakhstan become SFMs at the moment of registration, and which notifications that requires, is examined in Permits and Notifications in Kazakhstan in 2026.
The legal framework of financial monitoring in Kazakhstan is a five-tier hierarchy: Law No. 191-IV itself; the codes on liability (the Code of Administrative Offences and the Criminal Code); the orders of the AFM as the authorised body; the acts of sector regulators on internal control rules for “their” sectors; and the acts of the President and the Government on strategy and risk-mitigation measures. No tier displaces another: the Law sets the duties, the AFM orders set the form and technique of performing them, the sector acts fill in the detail of the ICR, and the codes attach the sanctions. All references to statutory and subordinate provisions follow the consolidated texts of the Adilet legal information system, read on 10 September 2026; the commencement dates of amendments are cross-checked against the notes of the Paragraph information system.
|
Tier |
Instrument and particulars |
What it governs for SFMs |
|
1. Law |
Law of the Republic of Kazakhstan No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction” — published 8 September 2009, in force since 9 March 2010; text as amended as at 13 August 2026 |
The list of SFMs (Article 3), threshold and suspicious transactions (Article 4), due diligence (Articles 5–9), reporting (Articles 10, 10-1), internal control and risk assessment (Articles 11, 11-1), targeted financial sanctions (Articles 12, 12-1), beneficial owners (Articles 6-1, 12-3), refusal and freezing (Article 13), state control (Articles 14, 14-1) |
|
2. Codes |
Code of Administrative Offences No. 235-V of 5 July 2014, Articles 214 (in the wording of Law No. 247-VIII of 30 December 2025, in force since 2 March 2026), 214-1 and 463; Criminal Code No. 226-V of 3 July 2014, Articles 218 and 218-1 |
Administrative fines from 30 to 1,800 MCI and suspension of activity; criminal liability for laundering — up to 10 years’ imprisonment with confiscation |
|
3. AFM orders |
Order No. 13 of 22 February 2022 (Rules for Providing Information and indicators of suspicious transactions; as reworded by Order No. 22 of 23 December 2025, in force since 1 April 2026, with the amendments of Order No. 12 of 16 June 2026, in force since 12 July 2026); Order No. 4 of 6 August 2021 (ICR requirements for the non-financial sector; as reworded by Order No. 15 of 25 November 2025, in force since 12 December 2025); Order No. 6 of 9 August 2021 (training and testing; as reworded by Order No. 27 of 29 December 2025, in force since 20 January 2026); Order No. 18 of 8 December 2025 (personal account; in force since 26 December 2025); Order No. 5 of 25 September 2023 (register of beneficial owners; in force since 11 September 2023, amended by Order No. 21 of 23 December 2025 with effect from 17 January 2026) |
Form FM-1 and transmission channels, suspicion indicator codes 11–27, requirements for the responsible officer, the AML knowledge test, registration in the personal account, access to the register of beneficial owners |
|
4. Sector acts on ICR |
Resolution of the Board of the Agency for Regulation and Development of the Financial Market (ARDFM) No. 18 of 22 March 2020 (ICR for second-tier banks, branches of non-resident banks and the National Postal Operator; Requirements as reworded by Resolution No. 74 of 20 April 2026); ARDFM and National Bank acts for insurers, professional securities-market participants, payment organisations and digital-asset operators; Order of the Minister of Justice No. 705 of 28 November 2025 (notaries; in force since 13 December 2025); Order of the Acting Minister of Tourism and Sport No. 250 of 19 December 2025 (gambling and lotteries; in force since 6 January 2026); Order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development No. 192/НҚ of 8 April 2026 (postal operators; in force since 24 April 2026) |
Content of the ICR, frequency of customer-data updates, remote identification, training programmes |
|
5. Acts of the President and the Government |
Presidential Decree No. 1038 of 6 October 2022 approving the Concept for the Development of Financial Monitoring 2022–2026; Government Resolution No. 934 of 7 November 2025 approving measures to reduce the risks of laundering (in force since 20 November 2025) |
Target indicators (90 % of SFMs in the AFM information system by 2026); 44 measures with deadlines running to December 2027: new suspicion indicators, a register of high-risk crypto-wallets, methodological guidance for banks, real-estate agents and jewellers |
The amendment history of Law No. 191-IV. Since 2020 the Law has been amended by more than ten laws; the table lists the nine that changed the duties of SFMs and the law that rewrote Article 214 of the CAO. Adoption, first official publication and commencement dates are shown separately, because in Kazakhstan they almost never coincide: the standard formula “on the expiry of sixty calendar days after the day of first official publication” means commencement on the 61st day after publication.
|
Law |
Adopted |
Published |
In force |
Changes for SFMs |
|
No. 325-VI |
13 May 2020 |
14 May 2020 |
15 November 2020 |
Targeted financial sanctions for proliferation financing (Article 12-1), protection of charities (Article 12-2), recognition of suspicious transactions under the entity’s own ICR, enhanced due diligence for customers from countries with deficient implementation of FATF Recommendations |
|
No. 73-VII |
18 November 2021 |
19 November 2021 |
19 January 2022 |
Notification of commencement and termination of activity for legal consultants (other than advocates), lessors, jewellers and real-estate agents (paragraph 3 of Article 3) |
|
No. 131-VII |
1 July 2022 |
4 July 2022 |
3 September 2022 |
Duty of legal entities to identify their own beneficial owners (Article 12-3); Article 214-1 CAO on the liability of legal entities for laundering |
|
No. 23-VIII |
12 July 2023 |
13 July 2023 |
12 September 2023 |
Register of beneficial owners of legal entities (Article 6-1), as part of the asset-recovery legislation; Article 218-1 of the Criminal Code |
|
No. 113-VIII |
5 July 2024 |
6 July 2024 |
5 September 2024 |
Aims, tasks and principles of the Law (Articles 2-1, 2-2); refinements to Article 3 and to the AFM’s functions (Articles 15–17) |
|
No. 219-VIII |
19 September 2025 |
20 September 2025 |
20 November 2025 |
New title of the Law; a customer’s suspicious activity (Article 10-1); preventive control without a visit (Article 14-1); new wording of Article 11-1 on risk assessment; by the footnotes of the consolidated text the amendments touched 28 articles, including two new ones |
|
No. 247-VIII (CAO) |
30 December 2025 |
31 December 2025 |
2 March 2026 |
New wording of Article 214 CAO: 19 offences and four fine scales |
|
No. 256-VIII |
9 January 2026 |
10 January 2026 |
11 July 2026 |
Digitalisation: Articles 2-1, 6-1, 14-1, 16–18 (service of documents through the personal account) |
|
No. 259-VIII |
16 January 2026 |
17 January 2026 |
1 May 2026 (AML/CFT provisions) |
Five categories of digital-asset operators and issuers on the SFM list (sub-paragraphs 23)–27) of paragraph 1 of Article 3); thresholds for digital-asset transactions; register of crypto-wallets used for criminal purposes |
|
No. 311-VIII |
12 June 2026 |
13 June 2026 |
13 August 2026 |
New wording of the politically exposed person criterion for heads of international organisations established by states under international treaties |
Author’s assessment: as of September 2026 the regime has stabilised, but three duties have only just begun to apply. The first is reporting of suspicious activity under Article 10-1 (since 20 November 2025); the second is the updated suspicion indicators of AFM Order No. 13 (since 1 April 2026); the third is SFM status for digital-asset operators (since 1 May 2026). These are precisely the three areas in which the AFM, under Government Resolution No. 934, is drafting new typologies and indicators during 2026, so ICR adopted before November 2025 need revision. How the licensing regime for digital-asset operators — SFMs since May 2026 — is structured is described in Digital Assets and Mining in Kazakhstan 2026.
The list of subjects of financial monitoring is the closed list in paragraph 1 of Article 3 of Law No. 191-IV: SFM status arises neither by a decision of the AFM nor by registration in the personal account, but automatically — from the moment a person begins the activity named in one of the sub-paragraphs. State bodies are not SFMs (paragraph 2 of Article 3). The list contains 27 sub-paragraphs; sub-paragraphs 14) and 17) were deleted earlier, and sub-paragraph 20) was deleted with effect from 1 May 2026 by Law No. 259-VIII, which added sub-paragraphs 23)–27).
|
Group |
Sub-paragraphs of paragraph 1 of Article 3 |
Who is covered |
|
Banking and payments |
1), 10), 11), 12) |
Second-tier banks, branches of non-resident banks, organisations carrying out certain banking operations (except the interbank transfer system operator and cash-collection-only entities); postal operators providing money transfers; organisations carrying on microfinance activity — under Article 3 of Law No. 56-V of 26 November 2012 “On Microfinance Activity” these are microfinance organisations, pawnshops and credit partnerships; payment organisations |
|
Financial market |
2), 3), 4), 5) |
Exchanges, clearing organisations, commodity-exchange brokers, clearing centres of commodity exchanges; insurance (reinsurance) organisations, insurance brokers, mutual insurance societies, the Export Credit Agency, branches of non-resident insurers; the Unified Accumulative Pension Fund and voluntary accumulative pension funds; professional securities-market participants and the central depository |
|
Legal and accounting professions |
6), 7), 8) |
Notaries performing notarial acts involving money and property; advocates, legal consultants and other independent legal specialists — when acting for a client in real-estate transactions, the management of money, securities and accounts, the accumulation of funds to create and run companies, and the creation, purchase, sale and management of legal entities; accounting organisations, professional accountants in private practice, audit organisations |
|
Goods and services markets |
9), 13), 15), 16), 22) |
Gambling and lottery operators; individual entrepreneurs and legal entities acting as lessors without a licence; dealers in precious metals, precious stones and jewellery; intermediaries in real-estate sale and purchase (real-estate agents); mobile operators |
|
Quasi-public sector and the AIFC |
18), 19), 21) |
The Social Health Insurance Fund; AIFC participants carrying on activities determined by the Astana Financial Services Authority (AFSA) in agreement with the AFM; the State Corporation “Government for Citizens” |
|
Digital assets (since 1 May 2026) |
23), 24), 25), 26), 27) |
Operators of exchange of unsecured digital assets; operators of digital financial asset platforms; operators of digital-asset trading platforms; issuers of digital financial assets; participants of the National Bank’s special regulatory regime for digital assets |
Three start-up duties of SFM status. The first is a notification of commencement of activity: advocates are exempt, but legal consultants and other independent legal specialists, unlicensed lessors, dealers in precious metals and jewellery and real-estate agents must notify the AFM of the commencement or termination of their activity under Law No. 202-V of 16 May 2014 “On Permits and Notifications” (paragraph 3 of Article 3; item 35 of Annex 3 to Law No. 202-V); the AFM keeps the state electronic register of such notifications (sub-paragraphs 13-1) and 13-2) of Article 16). The second is registration in the personal account on the AFM portal, mandatory for all SFMs whether or not they have reportable transactions (paragraph 2-1 of Article 10): under the Rules for the Personal Account approved by AFM Order No. 18 of 8 December 2025, the entity enters its IIN or BIN, the portal checks the type of activity automatically, and if there is a mismatch the entity sends supporting documents (a licence, a notification, a qualification certificate, the charter) within three working days, after which the AFM decides on access within three working days. The third is uploading to the personal account the results of the risk-exposure assessment of the entity’s services, the ICR and the test certificate (paragraph 8 of the Rules).
Who sets the ICR requirements and who inspects. The Law divides competence along two lines: the ICR requirements (paragraph 3-2 of Article 11) and state control (Article 14). The table shows how that works for five typical categories.
|
Parameter |
Second-tier bank (sub-para. 1)) |
Notary (sub-para. 6)) |
Legal consultant, accounting firm (sub-paras. 7), 8)) |
Real-estate agent, jeweller, lessor (sub-paras. 13), 15), 16)) |
Digital-asset exchange operator (sub-para. 23)) |
|
ICR requirements set by |
ARDFM in agreement with the AFM (Resolution No. 18 of 22 March 2020) |
Ministry of Justice in agreement with the AFM (Order No. 705 of 28 November 2025) |
AFM (Order No. 4 of 6 August 2021) |
AFM (Order No. 4 of 6 August 2021) |
National Bank in agreement with the AFM |
|
State control by |
ARDFM |
Ministry of Justice |
AFM (except audit organisations and advocates) |
AFM |
The regulator under the digital-assets legislation, within its competence |
|
Notification of commencement to the AFM |
No (ARDFM licence) |
No (licence) |
Yes for legal consultants and independent specialists; no for advocates and accountants |
Yes |
No (authorisation under the digital-assets legislation) |
|
Registration in the AFM personal account |
Mandatory |
Mandatory |
Mandatory |
Mandatory |
Mandatory |
|
Responsible officer |
Head of a unit with an impeccable reputation (paragraph 3 of Article 11) |
The notary personally |
Head of a unit; an individual entrepreneur appoints himself or herself |
Head of a unit; an individual entrepreneur appoints himself or herself |
Under National Bank requirements |
|
AML knowledge test |
Responsible officer — before taking up the function; result valid three years |
Sole practitioner — within three months of starting activity |
Responsible officer — before taking up the function; sole practitioner — within three months |
Responsible officer — before taking up the function; sole practitioner — within three months |
Responsible officer — before taking up the function |
|
AFM preventive control without a visit (Article 14-1) |
No |
No |
Yes |
Yes |
No |
Author’s assessment: the greatest risk of an inadvertent breach lies with businesses that do not think of themselves as “financial”. An accounting firm keeping clients’ books, a law firm registering LLPs for clients, a real-estate agency or a jewellery shop becomes an SFM by virtue of its activity and falls under the AFM’s direct control — including preventive control without a visit, in which a compliance notice is issued on the basis of state information systems without any inspector calling. A foreign investor opening a company in Kazakhstan in these fields should build SFM status into the launch plan alongside registration and tax accounting; the LLP registration procedure and the related duties are described in LLP (TOO) in Kazakhstan for Foreigners 2026.
A threshold transaction is a transaction in money or other property that an SFM must report to the AFM solely because its amount equals or exceeds a threshold fixed in paragraph 1 of Article 4 of Law No. 191-IV — whether or not the transaction shows any indicator of suspicion. The thresholds are expressed in tenge; for foreign-currency transactions the equivalent at the market rate on the day of the transaction applies, and for unsecured digital assets the equivalent at their market value on that day. A threshold transaction is reported no later than the working day following the day it is carried out (paragraph 2 of Article 10). Below is the complete scale of thresholds in the wording in force since 1 May 2026.
|
Threshold, KZT |
Transactions (sub-paragraph of paragraph 1 of Article 4) |
Form of settlement |
|
1,000,000 |
Receipt of winnings from betting, gambling in gambling establishments and lotteries, including electronic ones; purchase and sale of cultural valuables, their import and export (sub-para. 1)) |
Cash for cultural valuables; any form for winnings |
|
3,000,000 |
Pawnshop transactions in money, securities, precious metals and stones, jewellery and other valuables (sub-para. 1-1)) |
Cash and non-cash |
|
5,000,000 |
Transfers abroad to anonymous accounts and receipts from anonymous accounts; purchase and sale of jewellery; credits and transfers from persons registered, resident or located in an offshore zone or holding an account with a bank in an offshore zone, and transactions with such persons; money transactions to or from operators of exchange of unsecured digital assets, trading-platform operators, National Bank special-regime participants and AIFC licensees; credits and transfers of unsecured digital assets and transactions of such operators’ clients (sub-para. 2)) |
Cash and non-cash |
|
7,000,000 |
Payments and transfers of money to another person free of charge; transactions in shares and units of investment funds, including those issued on a digital financial asset platform (except repo on the organised market); transactions in digital financial assets under sub-paragraphs 1) and 2) of Article 5 of the Law on Digital Assets (sub-para. 3)) |
Cash and non-cash |
|
10,000,000 |
Purchase, sale and exchange of foreign currency through exchange offices; withdrawal and deposit of cash to a bank account, issue and receipt of cash; transactions of legal entities registered less than three months earlier; insurance payouts and premiums in cash; voluntary pension contributions and payouts in cash; cash payment under contracts for work, carriage, forwarding, storage, commission and trust management (except safe-deposit rental); receipt of money under a cheque or bill in cash; import and export of cash currency, bills and cheques, except by the National Bank, banks and the National Postal Operator (sub-para. 4)) |
As specified in the sub-paragraph |
|
45,000,000 |
Receipt and provision of property under a financial lease; transactions in bonds and government securities (except repo); transactions in digital financial assets under paragraph 3 of Article 5 of the Law on Digital Assets (sub-para. 5)) |
Cash and non-cash |
|
50,000,000 |
Transactions of a customer that received a loan under National Fund business-financing programmes (sub-para. 6)); real-estate transactions transferring title (sub-para. 8)); sale and purchase of movable property transferring title, and of precious metals and stones, except sales of refined gold and other sales to the National Bank, purchases of reference samples and purchases from subsoil users holding a mining licence (sub-para. 9)) |
Cash and non-cash |
|
100,000,000 in foreign-currency equivalent |
Cross-border payments and transfers to and from a customer’s bank account (sub-para. 7)) |
Non-cash |
|
500,000,000 |
Exchange transactions in commodities on a commodity exchange (sub-para. 10)) |
Non-cash |
Four rules for applying the thresholds. First, the threshold is compared with the amount of the individual transaction, not with the customer’s turnover over a period: systematic sub-threshold transactions are not themselves threshold transactions, but they constitute the “structuring” indicator of suspicion (code 24 of Annex 2 to AFM Order No. 13). Second, the duty to report rests with every SFM through which the transaction passes: a KZT 50,000,000 real-estate deal generates a report from the notary certifying the contract, from the real-estate agent acting as intermediary and from the bank processing the payment. Third, a threshold transaction is reported in every case, not only where the customer has failed to explain its economic rationale; examining the rationale belongs to mandatory scrutiny under paragraph 4 of Article 4. Fourth, Law No. 191-IV neither defines “offshore zone” for the KZT 5,000,000 threshold nor refers to a specific list — the dedicated Ministry of Finance list for the purposes of the AML Law (Order No. 52 of 10 February 2010) was repealed with effect from 15 November 2020 — so the list the SFM applies should be set out in its ICR in the light of AFM guidance and sector lists (for example, ARDFM Resolution No. 8 of 24 February 2020 for banking and insurance).
Author’s assessment: the scale of thresholds is the most frequent source of omissions among non-financial SFMs. A real-estate agent earning a commission monitors the price of the property, not the fee: a flat sold for KZT 55,000,000 is a threshold transaction for the agent, the notary and the bank at once; a bank processing a customer’s gratuitous transfer of KZT 7,000,000 reports under sub-paragraph 3); and a jewellery salon reports every sale from KZT 5,000,000 under sub-paragraph 2), even where the buyer paid by card. Companies opening an account with a bank in Kazakhstan for foreign-trade settlements should keep in mind the KZT 100,000,000-equivalent threshold for cross-border transfers, which the bank applies automatically: the practical steps for a non-resident opening an account are described in Opening a Bank Account in Kazakhstan for a Foreign Company and a Non-Resident, and the interaction with currency control in Currency Control in Kazakhstan 2026.
A suspicious transaction is a customer’s transaction — including an attempted transaction, one in progress and one already completed — in relation to which suspicions arise that the money or other property used is the proceeds of criminal activity, or that the transaction itself is aimed at laundering the proceeds of crime, financing terrorism, financing the proliferation of weapons of mass destruction or other criminal activity (sub-paragraph 1) of Article 1 of Law No. 191-IV). Unlike threshold transactions, suspicious transactions are subject to financial monitoring regardless of their form and amount (paragraph 3 of Article 4). It is the SFM itself that recognises a transaction as suspicious — either under the programmes implementing its ICR or as a result of mandatory scrutiny. A customer’s suspicious activity is a new concept introduced by Law No. 219-VIII: a set of two or more suspicious transactions (sub-paragraph 4-1) of Article 1), reported separately under Article 10-1.
Four grounds for mandatory scrutiny (paragraph 4 of Article 4). An SFM must examine a transaction if it is complex or unusual in nature, has no obvious economic rationale or lawful purpose, or is unusually large for the customer; is accompanied by actions aimed at evading due diligence or monitoring; is presumably aimed at cashing out the proceeds of crime; or is carried out with persons registered or resident in a state that fails, or insufficiently, to implement the FATF Recommendations, or through an account with a bank in such a state — according to the list compiled by the AFM on the basis of FATF documents and posted on its website. Transactions that match typologies and schemes approved by the AFM and posted on its website are also subject to monitoring (paragraph 5 of Article 4). The outcome of scrutiny is recorded: under paragraph 22 of the ICR Requirements for the non-financial sector (AFM Order No. 4), a decision to treat a transaction as suspicious is documented with its date and grounds.
Indicators of suspicion. Annex 2 to AFM Order No. 13 of 22 February 2022, in the wording in force since 1 April 2026, contains 17 groups of indicators with codes 11–27, which are entered on Form FM-1.
|
Code |
Group of indicators (Annex 2 to AFM Order No. 13) |
|
11 |
Payments and transfers by individuals inconsistent with their income and social status |
|
12 |
Registration of assets in the names of nominees |
|
13 |
Use of legal entities and individual entrepreneurs through sham transactions |
|
14 |
Large turnover of a company or entrepreneur without commensurate income or genuine activity |
|
15 |
Use of structures whose beneficial owners are hard to determine: offshore entities, trusts, multi-layer chains |
|
16 |
Digital-asset transactions and wallets linked to illegal activity |
|
17 |
Cash transactions: deposits, cash-outs, frequent large ATM withdrawals, especially abroad; cash couriers |
|
18 |
Foreign-trade payments without economic benefit |
|
19 |
Cross-border transactions through high-risk jurisdictions and informal transfer systems |
|
20 |
Suspicious transactions in securities and on exchanges |
|
21 |
Concealment of the illegal origin of funds through bets, sham loans, leasing, insurance and pension contributions |
|
22 |
High-risk foreign-exchange transactions under the national risk assessment, including capital flight and evasion of currency legislation |
|
23 |
Movement of funds of non-profit and charitable organisations |
|
24 |
Deposit transactions, including systematic sub-threshold transactions (structuring) |
|
25 |
Acquisition of property, including luxury goods, for cash or in a single payment |
|
26 |
Investment in legitimate business without sufficient income |
|
27 |
Other unusual transactions: property of unexplained origin, professional launderers, companies profiting from raising money |
Deadlines. A report of a suspicious transaction is filed before the transaction is carried out; where the transaction is recognised as suspicious only after it has been carried out, no later than 24 hours after recognition (paragraph 2 of Article 13), and the interval between execution and recognition may not exceed the review frequency fixed in the ICR. A report of a customer’s suspicious activity is filed no later than three working days after the day the activity is recognised as suspicious (Article 10-1). Transactions matching AFM typologies are reported no later than the working day following recognition (paragraph 2 of Article 10).
Author’s assessment: the list of indicators will keep growing in 2026, and the ICR must allow for that.Government Resolution No. 934 of 7 November 2025 instructs the AFM, between March and June 2026, to add to Order No. 13 indicators for transactions involving “drops” — persons who have given third parties access to their bank accounts or payment instruments — for cash-outs, sham loans, purchases and sales of vehicles and the use of legal entities and foreign structures for criminal purposes, and to build a register of high-risk crypto-wallets by December 2026. For an SFM this means that the monitoring programme must contain a mechanism for updating codes and typologies rather than a fixed list; according to the AFM’s report for 2025, it blocked more than 1,100 illegal online crypto-exchange services and 20,000 drop cards, so customer transactions showing the features of codes 16 and 17 are the first thing an inspection looks at.
Customer due diligence is the set of measures laid down in Article 5 of Law No. 191-IV that an SFM must apply to a customer, its representative and its beneficial owner when establishing a business relationship, when carrying out transactions subject to monitoring (including suspicious ones), and when doubts arise about the reliability of information obtained earlier (paragraph 2 of Article 5). The identification measures and the establishment of the purpose of the relationship are completed before the business relationship is established (Article 6) and before a transaction is carried out if due diligence has not been performed earlier (Article 7).
The seven due-diligence measures (sub-paragraphs 1), 2), 2-1), 2-2), 4), 5) and 6) of paragraph 3 of Article 5). First, identification of an individual by IIN, by the particulars of the identity document (where there is no IIN) and by legal address. Second, identification of a legal entity by its state-registration data, BIN, nature of activity and address. Third, identification of a foreign structure without legal personality by its name, registration number, address, place of principal activity and nature of activity and, for trusts, by the assets under management, the settlors and the beneficiaries. Fourth, identification of the beneficial owner from the constituent documents, the shareholder register, the register of beneficial owners of legal entities and other sources; where the customer’s information conflicts with the register and there are sufficient grounds to believe that the legal entity is involved in laundering, terrorist financing or proliferation financing, the SFM must terminate the business relationship or refuse to establish it. Fifth, establishing the intended purpose and nature of the business relationship. Sixth, ongoing monitoring of the relationship and scrutiny of transactions, including, where necessary, the source of funds. Seventh, verification of the data and its updating: once doubts arise, the information is updated within 15 working days after the day the decision that doubts exist is taken. Customers must provide the information requested, including data on beneficial owners, tax residence, type of activity and source of funds (paragraph 5 of Article 5).
Exemptions for one-off transactions (paragraph 3-1 of Article 5). Due diligence is not performed for certain one-off transactions below fixed amounts — in most cases only for individual customers, and provided the transaction is not suspicious.
|
Transaction |
Exemption threshold, KZT |
|
Cash deposit by an individual customer to an individual’s account, or payment for services through a cash-acceptance device |
500,000 |
|
Non-cash payment or transfer without opening a bank account |
500,000 |
|
Purchase, sale or exchange of cash foreign currency by an individual at an exchange office |
500,000 |
|
Retail purchase of jewellery by an individual |
500,000 |
|
Purchase of refined gold bars by an individual at an exchange office |
500,000 |
|
Transaction by an individual with a payment card that is not a means of access to his or her bank account |
200,000 |
|
Payment of an insurance premium by an individual under an insurance contract |
100,000 |
|
Payments in enforcement proceedings to state bodies through cash-acceptance devices; premiums and payouts under compulsory insurance |
No threshold |
Simplified and enhanced measures (paragraph 7 of Article 5). At a low level of risk the SFM may apply simplified due diligence — update identification data and review the relationship less often, and infer the purpose of the relationship from the nature of the transactions; simplified due diligence is prohibited where there is suspicion or high risk. At a high level of risk, enhanced due diligence applies: establishing the reasons for transactions, increasing the frequency of checks, obtaining information on the customer’s activity and source of funds, and approval by a senior manager. Enhanced due diligence is mandatory for customers from jurisdictions that fail to implement the FATF Recommendations (paragraph 10 of Article 5); reliance on due diligence performed by organisations in such jurisdictions, and outsourcing to them, are prohibited. Any SFM may entrust due diligence to another person, including another SFM, under a contract, but responsibility for compliance remains with the SFM (paragraph 8 of Article 5); reliance on due diligence already performed by another SFM or by a foreign financial institution is open only to financial-sector entities — banks, exchange and clearing organisations, insurers, pension funds, professional securities-market participants, microfinance organisations and payment organisations (sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3) — on condition that the data are obtained immediately and the documents are retained for five years (paragraph 6 of Article 5).
Establishing relationships remotely (paragraph 9 of Article 5). The requirements for remote identification by banks (other than entities carrying out only currency-exchange operations), exchange and clearing organisations (other than commodity exchanges), insurers, pension funds, professional securities-market participants and microfinance organisations are set by the ARDFM in agreement with the AFM; for AIFC participants, by the AFSA. A relationship may not be established remotely with persons on the terrorist-financing and proliferation-financing lists, with persons under UN Security Council sanctions, or with high-risk customers (except electronic insurance through bank accounts). For banks, ARDFM Resolution No. 18 requires biometric authentication through the Identity Data Exchange Centre and retention of the video-session recording for at least five years after the relationship ends.
Politically exposed persons (Article 8; the Law’s term is “public officials”). For foreign politically exposed persons — foreign public officials, persons performing public functions for a foreign state and heads of international organisations — the SFM must additionally: check whether the customer and the beneficial owner are connected to a politically exposed person, his or her spouse and close relatives; assess that person’s reputation; obtain written approval from a senior manager for establishing or continuing the relationship; take available measures to establish the source of funds; and apply enhanced due diligence on an ongoing basis. The same measures apply to Kazakhstan’s own politically exposed persons on the list approved by the President, and to their spouses and close relatives, who have been assigned a high level of risk — and continue to apply for 12 months after the official leaves office (paragraph 4 of Article 8). Since 13 August 2026, Law No. 311-VIII has refined the criterion for heads of international organisations established by states under international treaties.
Author’s assessment: a mismatch with the register of beneficial owners has become a risk for the customer, not only for the SFM. Since the creation of the state register of beneficial owners in 2023, the fourth due-diligence measure has required the customer’s information to be checked against it, and the current wording of sub-paragraph 2-2) of paragraph 3 of Article 5 expressly obliges the SFM to end the relationship where a mismatch coincides with sufficient grounds to suspect involvement in laundering. For a foreign-owned company this means that the data on ultimate owners filed at registration must match what the company tells its bank, its notary and its auditor; how the ownership structure of an LLP is arranged, and how the choice between an LLP and an AIFC participant is made, is examined in AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026.
A beneficial owner is an individual who directly or indirectly holds more than 25 % of the participatory interests in the charter capital or of the placed shares of a legal entity, or who otherwise controls the customer, or in whose interest the customer carries out transactions in money and other property (sub-paragraph 3) of Article 1 of Law No. 191-IV). The concept operates in three regimes at once: as the object of an SFM’s due diligence (Article 5), as the content of the state register (Article 6-1) and as the subject of an independent duty of every legal entity (Article 12-3).
The register of beneficial owners of legal entities (Article 6-1, introduced by Law No. 23-VIII of 12 July 2023) is a state database kept by the AFM. It records the legal entity’s name and BIN, its legal form, address and the particulars of its head, and for each beneficial owner — full name, identity-document particulars, date and place of birth, address, citizenship, IIN and the size of the holding. The register is populated through integration with state information systems, from law-enforcement information, on request, from information submitted by legal entities and from SFM findings; access is granted to supervisory state bodies, law-enforcement and special state bodies and SFMs themselves. Under the Rules approved by AFM Order No. 5 of 25 September 2023, the register sits in the closed part of the AFM web portal, is searched by IIN or BIN, and each entry carries a status: registration-based — the beneficial owner was declared at state registration in the “Legal Entities” database — or presumed, computed by the AFM through the ownership chain. An SFM that finds, in the course of due diligence, a discrepancy between the customer’s data and the register reports it through the personal account.
The legal entity’s own duties (Article 12-3, introduced by Law No. 131-VII of 1 July 2022). Every legal entity and every foreign structure without legal personality must: identify its beneficial owners on the form approved by the AFM in agreement with the Ministry of Justice; verify the information; update it at least once a year or on any change; keep it for at least five years; and provide it to the AFM on request. Founders, participants and controlling persons must supply the company with the necessary data. For late provision of the information on an AFM request, part 6 of Article 214 of the CAO provides a warning or a fine of 40 to 400 MCI; for failure to provide it or for false information, part 7 provides 45 to 420 MCI (280 MCI, or KZT 1,211,000, for a medium-sized enterprise). The duty does not extend to state institutions and quasi-public entities.
Author’s assessment: Article 12-3 makes every LLP a participant in the AML system even if it is not an SFM. An ordinary trading company files no reports with the AFM, but it must keep an up-to-date internal beneficial-owner questionnaire, update it annually and answer any AFM request — and when a participatory interest is sold or a controlling person changes, the data must change in the register, in the questionnaire and in the information previously given to the bank. Companies with a holding structure running through the UAE or Hong Kong will find it useful to compare the Kazakhstan standard with the beneficial-ownership disclosure requirements of those jurisdictions, described in The UAE UBO Register and goAML and Kazakhstan + UAE: The Dual Structure in 2026.
A report to the AFM is an electronic document on Form FM-1 that an SFM sends to the authorised body about a transaction subject to financial monitoring, a customer’s suspicious activity, a refusal of service or the freezing of transactions. The procedure is laid down in Article 10 of Law No. 191-IV and in the Rules for Providing Information approved by AFM Order No. 13 of 22 February 2022 (as reworded by Order No. 22 of 23 December 2025, in force since 1 April 2026, with the amendments of Order No. 12 of 16 June 2026, in force since 12 July 2026). Reports are filed in Kazakh or Russian through dedicated channels: the personal account, the external gateway of e-government, API services or the networks of the National Bank’s National Payment Corporation (paragraph 2 of the Rules). Form FM-1 is generated in XML, signed with the electronic digital signature of the responsible officer, and has four sections: form data, SFM data, particulars of the transaction or suspicious activity, and particulars of the participants (paragraphs 3–4 of the Rules). The cost of transmitting information is borne by the SFM (paragraph 4 of Article 10).
|
Event |
Reporting or action deadline |
Provision |
|
Threshold transaction (paragraph 1 of Article 4) |
No later than the working day following the transaction |
Paragraph 2 of Article 10 |
|
Suspicious transaction detected before execution |
Before the transaction is carried out |
Paragraph 2 of Article 13 |
|
Transaction recognised as suspicious after execution |
No later than 24 hours after recognition |
Paragraph 2 of Article 13 |
|
Customer’s suspicious activity (two or more transactions) |
No later than three working days after the day of recognition |
Article 10-1 |
|
Transaction matching an AFM typology (paragraph 5 of Article 4) |
No later than the working day following recognition |
Paragraph 2 of Article 10 |
|
Refusal to establish a relationship, termination of a relationship, refusal of a transaction |
No later than the working day following the decision |
Paragraph 2 of Article 13 |
|
Freezing of transactions under the lists |
No later than the working day following the measures |
Paragraph 2 of Article 13 |
|
AFM notice of acceptance or rejection of a report |
Within four hours |
Paragraph 6 of the Rules |
|
Correction of a rejected report |
Within 24 hours (excluding weekends and public holidays) |
Paragraph 6 of the Rules |
|
Correction of an accepted report on discovery of an error |
No later than the next working day |
Paragraph 6 of the Rules |
|
AFM decision to suspend or permit a suspicious transaction |
Within 24 hours of receipt of the report |
Paragraph 3 of Article 13; paragraph 7 of the Rules |
|
Answer to an AFM request for information and documents |
Within three working days of receipt; for a request within the analysis of a suspicious transaction — no later than the working day on which the request is received |
Paragraph 3-1 of Article 10 |
|
Extension of the three-day deadline on the SFM’s written application (at the AFM’s discretion) |
By no more than 10 working days |
Paragraph 3-1 of Article 10 |
|
Answer of a money-transfer system operator to a bank’s request |
Two working days |
Paragraph 3-2 of Article 10 |
|
Technical failure of channels or software confirmed by the AFM |
The report is deemed timely if filed within one working day after the failure is remedied |
Paragraph 8 of the Rules |
Who does not report. Advocates, legal consultants and other independent legal specialists do not report information obtained while representing and defending a client before the bodies of inquiry and preliminary investigation and in court, or while providing legal assistance in the form of consultations, explanations, written opinions and the drafting of statements of claim and other legal documents; notaries do not report notarial acts not involving money or property, or consultations (paragraph 3 of Article 10). The exemption does not cover support of real-estate transactions, management of client funds or the creation of companies — the very operations for which lawyers are on the SFM list.
What is not a breach of confidentiality. Filing reports and documents with the AFM is not a disclosure of commercial, banking or other legally protected secrecy and does not breach personal-data legislation (paragraph 6 of Article 11), and an SFM, its employees and its officers bear no liability under law or contract for a report filed in the prescribed manner, whatever its outcome (paragraph 7 of Article 11).
Author’s assessment: the 24-hour window for corrections is the typical point of exposure to a fine under part 12 of Article 214 of the CAO. The Rules provide for rejection of a report with a notice within four hours and re-filing within 24 hours; until the corrected report is accepted, the duty to report the threshold transaction remains unperformed, and because the report itself must go out on the next working day, an SFM without an on-duty responsible officer effectively has no margin of time at all. A company becoming an SFM for the first time is well advised to make a test filing in the personal account before its first real transaction and to set out in its ICR who signs the form when the responsible officer is absent; UPPERSETUP’s accounting support can help set up the internal records and the allocation of roles.
Internal control rules (ICR) are the SFM’s internal document which, under paragraph 3 of Article 11 of Law No. 191-IV, is approved by its executive body (or by the entity itself if it has no legal personality) with regard to the results of the risk-exposure assessment of its services and to the size, nature and complexity of its activity, and which must include at least five programmes: a programme for organising internal control, with the appointment of a responsible officer; a risk-management programme with two levels of risk (high and low) that also covers new-technology risks; a customer-identification programme; a programme for monitoring and scrutinising transactions, including complex, unusually large and other unusual transactions; and a training programme. The ICR requirements for the non-financial sector are set by AFM Order No. 4 of 6 August 2021 as reworded by Order No. 15 of 25 November 2025; the ICR are uploaded to the personal account (paragraph 4 of the Requirements). Financial groups may adopt single ICR for the entities in sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3 — banks, exchange and clearing organisations, insurers, pension funds, professional securities-market participants, microfinance organisations and payment organisations.
The responsible officer. Under paragraph 3 of Article 11 the responsible officer is appointed from among senior managers or heads of units not below the head of the relevant structural unit and must have an impeccable business reputation. For the non-financial sector, paragraph 6 of AFM Requirements No. 4 adds: an employment contract with the SFM, direct reporting to the head of the entity, higher or secondary professional education, at least two years’ experience in AML/CFT or in the entity’s field of activity, and a test certificate uploaded to the personal account; an individual entrepreneur or an individual appoints himself or herself, and only the certificate requirement applies. A person standing in for the responsible officer during leave, illness or a business trip must meet the same requirements, and the procedure for such substitution forms part of the programme for organising internal control (paragraphs 5–6 of the Requirements).
Training and testing (AFM Order No. 6 of 9 August 2021 as reworded by Order No. 27 of 29 December 2025). The responsible officer and the staff of the AML/CFT unit sit the test on the AFM website online, under biometric control, before taking up their functions; entities practising alone — within three months of starting activity. The test has 100 questions to be answered in 100 minutes; the pass mark is at least 70 correct answers; a resit is allowed after 14 calendar days; the result is valid for three years; the AFM keeps records of those who have been tested. The training programme covers AML/CFT legislation and the FATF standards, the entity’s ICR, liability under Articles 214 and 214-1 of the CAO, and typologies and indicators; additional training is held when the legislation or the ICR change.
Periodic ICR duties (AFM Requirements No. 4 for the non-financial sector). A review of the internal control system at least once a year by external or internal audit or by an employee not involved in AML/CFT, with a written report (paragraph 7); updating of data on high-risk customers at least once every six months (paragraph 15); risk assessment of new products before launch (paragraph 16); an annual assessment of the exposure of customers and services to risk, with the results uploaded to the personal account by 10 January of the following year (paragraph 17). For banks, ARDFM Resolution No. 18 requires data on high-risk customers to be updated at least once a year and, for certain categories, quarterly. Beyond its own ICR, under Article 11-1 every SFM must document and update its own risk assessment, take account of the national and sectoral assessments, and classify customers by risk level.
Record-keeping and the confidentiality of reports (paragraphs 4 to 5-1 of Article 11). Due-diligence documents, including the customer file, account data and correspondence, are kept for at least five years from the end of the business relationship; documents on transactions, including threshold and suspicious ones, and the results of scrutiny of unusual transactions — for at least five years after the transaction, in a form that allows the transaction, including amounts and currencies, to be reconstructed. An SFM and its employees may not inform customers or other persons of the AML/CFT measures taken — other than telling the customer of a freeze, a refusal to establish a relationship or a refusal of a transaction — or of receipt from the AFM of a list of persons carrying out suspicious transactions; a breach of this prohibition is punishable under part 17 of Article 214 of the CAO by a fine of 75 to 640 MCI with no warning option. Five-year retention of customer files has to be reconciled with personal-data legislation — retention periods, database localisation and the grounds for processing are described in Personal Data and Localisation in Kazakhstan in 2026.
Author’s assessment: the responsible officer is the one position for which the Law requires status, experience and a certificate all at once, and it is the one most often filled as a formality. Appointing an accountant or a lawyer as a secondary appointment without two years’ experience, without uploading the certificate to the personal account and without genuine reporting to the head makes the ICR non-compliant (part 15 of Article 214 CAO — up to 700 MCI), and in an AFM inspection the absence of a certificate is detected automatically from the personal-account data. For businesses whose volume of transactions does not justify a full-time specialist, it is more practical to split the functions: a responsible officer from among the managers on the payroll, with the ICR methodology, the annual internal-control review and test preparation supported externally; UPPERSETUP’s legal support offers that form of assistance.
Refusal, freezing and suspension are three different instruments of Article 13 of Law No. 191-IV with different grounds and deadlines. Refusal is the SFM’s own decision; freezing is the automatic consequence of a person’s inclusion in the lists published by the AFM; suspension is a decision of the AFM or a law-enforcement body on a specific transaction.
Refusal (paragraph 1 of Article 13). An SFM must refuse to establish a business relationship if it is impossible to identify the customer, its representative and its beneficial owner and to establish the purpose of the relationship; it must refuse to carry out a transaction and/or terminate the relationship if it is impossible to take the same measures and to verify the data; and it may refuse or terminate the relationship on suspicion of laundering, terrorist financing or proliferation financing. Refusals and terminations are reported to the AFM no later than the next working day (paragraph 2 of Article 13). Refusal and termination give rise to no civil liability of the SFM under the contract (paragraph 6 of Article 13).
Freezing (Articles 12, 12-1; paragraph 1-1 of Article 13). The AFM maintains and posts on its website the list of organisations and persons connected with the financing of terrorism and extremism and the list of organisations and persons connected with the financing of the proliferation of weapons of mass destruction, and, at the request of a foreign competent authority, a list of persons involved in terrorist activity. Within 24 hours of the list being posted or a person being added to it, the SFM must immediately suspend debit transactions on the bank accounts of that person, of customers whose beneficial owner it is, of organisations under its control and of persons acting on its behalf (except account-servicing operations), suspend the execution of payment instructions given without opening a bank account, block securities, refuse insurance payouts and premium refunds and refuse other transactions — except credits to the account and mandatory pension contributions. Extensions of deposits and debits to repay loans, leases and microcredits under contracts concluded before listing are permitted, as are transactions under a court decision and tax-authority collection orders. An individual listed on domestic grounds (sub-paragraphs 3)–6) of paragraph 4 of Article 12) may receive living expenses — wages up to the minimum wage per family member per month, pensions and benefits — and pay taxes and utilities (paragraph 8 of Article 12). Removal from a list takes place within one working day of the decision.
|
Measure |
Taken by |
Deadline |
Provision |
|
Freezing of transactions of listed persons |
SFM |
Within 24 hours of publication of the list |
Paragraph 1-1 of Article 13 |
|
Freezing under a list at the request of a foreign competent authority |
SFM |
Up to 15 calendar days |
Paragraph 10 of Article 12 |
|
Freezing at the request of a foreign financial intelligence unit |
SFM on notice from the AFM |
Within 24 hours; for up to 30 calendar days |
Paragraph 4-1 of Article 19-2 |
|
Decision on a suspicious-transaction report |
AFM |
Within 24 hours of receipt of the report |
Paragraph 3 of Article 13 |
|
Suspension of a suspicious transaction |
AFM |
Up to three working days |
Paragraph 3 of Article 13; Article 17 |
|
Decision of a law-enforcement or special body after suspension |
Law-enforcement body |
Within 72 hours; the AFM relays the decision to the SFM within three hours |
Paragraph 5 of Article 13 |
|
Suspension of debit transactions on accounts and e-money on a law-enforcement decision |
AFM |
Up to 15 calendar days |
Paragraph 5-1 of Article 13 |
|
Transactions under contracts concluded before listing on the proliferation-financing list |
AFM |
Suspension within 24 hours for up to 15 working days; decision within three working days |
Paragraph 6 of Article 12-1 |
Suspension of a suspicious transaction. Having reported a suspicious transaction before executing it, the SFM does not carry it out until the AFM decides; if no decision is received within 24 hours of filing the report, the transaction must be carried out unless other lawful grounds prevent it (paragraph 4 of Article 13). Failure to suspend a transaction on the AFM’s decision is punishable under part 14 of Article 214 of the CAO by a fine of 75 to 600 MCI. State bodies bear no liability for losses, including lost profit, caused by a suspension (paragraph 6 of Article 13).
Author’s assessment: freezing is the only SFM duty whose performance is measured in hours and does not depend on the size of the entity. The lists are updated in the ordinary course of business and the 24-hour period runs from the moment of posting on the AFM website, so the monitoring programme must provide for periodic screening of the entire customer base against the lists, not only a check when the relationship is established; for a jewellery salon or a real-estate agency without an automated system that is a daily manual procedure. Companies receiving payments in Kazakhstan from foreign counterparties should also consider the reverse side: blocking of a transaction under the proliferation-financing list is not a breach of contract by the bank (paragraph 6 of Article 13), so any dispute over the unexecuted payment will have to be pursued against the counterparty, not the bank.
State control in the AML/CFT field is, under Article 14 of Law No. 191-IV, the control that each supervisory body exercises within its own competence: the ARDFM over banks, insurers and professional securities-market participants; the National Bank over exchange offices and payment organisations; the regulators under the digital-assets legislation over digital-asset operators; the Ministry of Justice over notaries; and the AFM directly over legal consultants and independent legal specialists (other than advocates), accounting organisations and professional accountants (other than audit organisations), lessors, jewellers, real-estate agents, the Social Health Insurance Fund, the State Corporation and mobile operators. The AFM uses three forms: unscheduled inspections, preventive control with a visit and preventive control without a visit to the entity.
Preventive control without a visit (Article 14-1, introduced by Law No. 219-VIII). The AFM analyses information from the media and from state information systems — including personal-account data — and, on detecting a breach, issues a compliance notice within 10 working days; the notice is deemed served when handed over against signature, sent by post or courier, or posted in the personal account. The entity must, within the period stated in the notice but not less than 10 working days, submit a letter with supporting materials or a remediation plan; objections may be lodged within 10 working days. Failure to comply with the notice leads to inclusion in the half-yearly list for preventive control with a visit. Separately, supervisory bodies must carry out a sectoral risk assessment once every three years (sub-paragraph 6) of paragraph 1 of Article 18), and SFMs must take its results into account in their own risk assessment (Article 11-1).
Policy documents. Presidential Decree No. 1038 of 6 October 2022 approved the Concept for the Development of Financial Monitoring 2022–2026: according to it, the number of SFMs covered by the AML/CFT system grew from 6,000 to 9,000 over 2019–2021 (2,000 in the financial sector, 7,000 in the non-financial sector), while over the same period entities filed more than 5 million reports, 99 % of them from the financial sector; the target indicators for 2026 are 90 % of SFMs registered in the AFM information system and 35 “compliant” or “largely compliant” ratings on the FATF Recommendations. Government Resolution No. 934 of 7 November 2025 approved 44 measures with deadlines running to December 2027, on which the AFM reports to the Government twice a year.
Results for 2025. According to the AFM Chairman’s report to the President on 12 January 2026, in 2025 the investigation of 1,135 criminal cases was completed, KZT 141.5 billion was recovered for victims, 15 criminal groups and 29 cash-out platforms with a turnover of over KZT 128 billion were dismantled, 22 shadow crypto-exchangers were shut down, more than 1,100 illegal online crypto-exchange services and 20,000 drop cards were blocked; the financial sector terminated business relationships with 2,000 companies and 56,000 individuals on suspicion of laundering, and criminal online-casino flows of KZT 2.1 trillion passed with the complicity of 35 payment organisations.
International assessment. Kazakhstan is a co-founder of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), a FATF-style regional body. The third-round mutual evaluation report was adopted at the 38th EAG Plenary on 8 June 2023, and the country was placed in regular follow-up. The first follow-up report with re-ratings was adopted by the EAG Plenary in May 2026 and published on 29 June 2026: the ratings on Recommendations 6, 7, 24 and 26 were upgraded from “partially compliant” to “largely compliant”, while Recommendation 28 — on the regulation and supervision of non-financial SFMs — remained “partially compliant”; as a result, Kazakhstan is rated “compliant” or “largely compliant” on 37 of the 40 FATF Recommendations and remains in regular follow-up. Kazakhstan does not appear on the FATF list of jurisdictions under increased monitoring of 19 June 2026 (22 jurisdictions).
Author’s assessment: the retained “partially compliant” rating on Recommendation 28 sets the AFM’s focus for 2026–2027. Recommendation 28 concerns the supervision of notaries, lawyers, accountants, real-estate agents, jewellers and gambling operators — precisely the entities the AFM supervises directly; the logical regulatory response is a rise in the number of compliance notices under Article 14-1 and of inspections in the non-financial sector, where, according to the Concept’s figures for 2019–2021, 7,000 of the 9,000 entities were concentrated but only 1 % of reports originated. For businesses in that sector the current year is the last opportunity to put the ICR, the personal account and the certificates in order before preventive control becomes systematic; Kazakhstan’s model of non-financial-sector supervision can be compared with the Emirati and Hong Kong models in DNFBP AML Compliance in the UAE 2026 and The Hong Kong TCSP Licence in 2026.
The liability of an SFM is built on three levels: administrative liability under Article 214 of the Code of Administrative Offences for breach of the duties themselves; administrative liability of a legal entity under Article 214-1 of the CAO for a transaction in property known to be the proceeds of crime; and criminal liability of individuals under Article 218 of the Criminal Code for laundering. Article 214 of the CAO applies in the wording of Law No. 247-VIII of 30 December 2025, in force since 2 March 2026, and contains 19 parts with four fine scales: for individuals; for officials, notaries and advocates, small-business entities and non-profit organisations; for medium-sized business entities; and for large-business entities and branches of non-resident banks, insurers and insurance brokers. The monthly calculation index (MCI) for 2026 is KZT 4,325 (sub-paragraph 4) of Article 7 of Law No. 239-VIII of 8 December 2025 “On the Republican Budget for 2026–2028”).
|
Part of Article 214 CAO |
Breach |
Individuals |
Officials, notaries, advocates, small business, NPOs |
Medium business |
Large business, branches of non-residents |
|
1 |
Breach of the rules on recording, storing and protecting information and documents |
30 |
70 |
210 |
280 |
|
2 |
Late report of a suspicious transaction or a transaction matching a typology |
Warning or 65 |
180 |
290 |
520 |
|
3 |
Failure to report, or knowingly false report of, a suspicious transaction |
75 |
210 |
330 |
600 |
|
4 |
Late answer to an AFM request |
Warning or 40 |
110 |
280 |
420 |
|
5 |
Failure to answer, or false information in answer to, an AFM request |
45 |
120 |
300 |
450 |
|
6 |
Late submission of beneficial-owner information on request (paragraph 5 of Article 12-3) |
Warning or 40 |
100 |
250 |
400 |
|
7 |
Failure to submit, or false, beneficial-owner information on request |
45 |
110 |
280 |
420 |
|
8 |
Failure to take due-diligence measures |
40 |
110 |
280 |
420 |
|
9 |
Breach of the freezing duties and of reporting of freezing |
75 |
195 |
330 |
600 |
|
10 |
Failure to refuse a customer or to report the refusal |
40 |
110 |
280 |
420 |
|
11 |
Failure to implement the training programme |
30 |
70 |
210 |
280 |
|
12 |
Late report of a threshold transaction |
Warning or 40 |
100 |
260 |
400 |
|
13 |
Failure to report, or false report of, a threshold transaction |
45 |
120 |
300 |
450 |
|
14 |
Failure to suspend a transaction on the AFM’s decision |
75 |
210 |
330 |
600 |
|
15 |
ICR not compliant with the legislation |
Warning or 110 |
180 |
320 |
700 |
|
16 |
Failure to develop and adopt ICR |
120 |
195 |
345 |
750 |
|
17 |
Tipping off customers and other persons about AML/CFT measures |
75 |
210 |
330 |
640 |
|
18 |
Repeat breach within a year under parts 1, 3, 5, 7–11, 13, 14, 16, 17 |
150 |
225 |
375 |
900 |
|
19 |
Breach under parts 1–17 three or more times within a year |
200 |
450 |
900 |
1,800 |
All amounts are in MCI. For a medium-sized enterprise the fine under part 3 is 330 MCI, or KZT 1,427,250; under part 16, 345 MCI, or KZT 1,492,125; under part 19, 900 MCI, or KZT 3,892,500; for large business and branches of non-resident banks, part 19 means 1,800 MCI, or KZT 7,785,000. Part 19 additionally entails suspension of the licence or qualification certificate for up to six months or their revocation, suspension of activity for up to three months, or a ban on the activity or certain of its types for up to three years. A warning instead of a fine is available only under parts 2, 4, 6, 12 and 15 — for late reports and answers and for non-compliant ICR, never for a failure to report.
Related offences. Article 214-1 of the CAO punishes a legal entity that carries out a transaction in money or property known to it to have been obtained by crime, where this results in laundering: 750 MCI for small-business entities and non-profit organisations, 1,000 MCI for medium-sized and 2,000 MCI (KZT 8,650,000) for large-business entities; voluntary disclosure of such a transaction exempts from liability. Article 463 of the CAO punishes activity without a mandatory notification with a fine of 15 to 150 MCI (40 MCI for a medium-sized enterprise) and, for a repeat offence, 30 to 500 MCI. Article 218 of the Criminal Code provides, for the laundering of proceeds of crime, a fine of up to 5,000 MCI or restriction or deprivation of liberty for up to six years with confiscation of property; where committed by a group, repeatedly or with the use of an official position — a fine of 3,000 to 7,000 MCI or imprisonment for three to seven years; and where committed on a large scale, by a criminal group or by an official using his or her position — imprisonment for five to ten years with confiscation; a person who voluntarily reports a planned or completed laundering is exempt from criminal liability unless his or her acts contain the elements of parts 2 or 3 of that Article or of another offence.
Author’s assessment: the economics of the fines have made inaction more expensive than compliance for any medium-sized enterprise. The simultaneous absence of ICR (part 16), failure to take due-diligence measures (part 8) and failure to report threshold transactions (part 13) — the typical set for a company unaware of its status — adds up to 925 MCI, or KZT 4,000,625, before any repeat; a repeat within a year moves each of those breaches into part 18 (375 MCI), and a third into part 19 with the risk of suspension of activity. A separate exposure is the head’s liability as an official on the second scale and the criminal risk under Article 218 where intent is proved; how that risk interacts with a director’s duties when the company is insolvent is described in Bankruptcy and Rehabilitation of Legal Entities in Kazakhstan in 2026.
The algorithm for launching an internal control system is a sequence of twelve steps that takes a company from “we did not know we were an SFM” to readiness for AFM preventive control. The order matters: the responsible officer’s test precedes adoption of the ICR, registration in the personal account precedes the first report, and the notification of commencement precedes everything else.
Step 1. Determine the status. Match the actual activity against the sub-paragraphs of paragraph 1 of Article 3 of Law No. 191-IV: for legal consultants the status arises only when they take part in five kinds of transactions on a client’s behalf, for accounting organisations — when they carry on accounting as a business, for real-estate agents — when they act as intermediaries in sales and purchases of real estate. Record the conclusion in writing with the sub-paragraph cited.
Step 2. File the notification of commencement of activity. For legal consultants and independent specialists, unlicensed lessors, dealers in precious metals and jewellery and real-estate agents — through the elicense.kz portal under item 35 of Annex 3 to Law No. 202-V, before starting activity; keep the receipt. Advocates, notaries, accountants and licensed entities do not file it.
Step 3. Appoint the responsible officer. By order of the head — from among senior managers or heads of units with an impeccable business reputation; for the non-financial sector, check the two years’ experience and the education required by paragraph 6 of AFM Requirements No. 4. An individual entrepreneur appoints himself or herself.
Step 4. Pass the test. The responsible officer and the staff of the AML/CFT unit sit the online test on the AFM website under biometric control before taking up their functions (100 questions, 100 minutes, at least 70 correct answers); sole practitioners — within three months. The certificate is valid for three years.
Step 5. Carry out a risk assessment. Document the entity’s own assessment of laundering, terrorist-financing and proliferation-financing risks under Article 11-1, taking into account the national and sectoral assessments, the AFM typologies and the FATF list; define the risk categories (country, customer, product, channel) and the two customer risk levels.
Step 6. Adopt the ICR. Draft the programmes — at least five — required by paragraph 3 of Article 11 and by the sector requirements (AFM Order No. 4 for the non-financial sector, ARDFM Resolution No. 18 for banks, Ministry of Justice Order No. 705 for notaries), have them approved by the executive body, and specify in the monitoring programme the frequency of transaction review — it determines the permissible interval between execution of a transaction and its recognition as suspicious.
Step 7. Register in the personal account. Enter the BIN or IIN on the AFM portal; if the type of activity does not match, send the documents within three working days; after authorisation, complete the organisation’s data and the data of the responsible persons and sign with the electronic digital signature. Upload the ICR, the risk-assessment results and the certificate.
Step 8. Set up due diligence. Introduce customer and beneficial-owner questionnaires, a check against the register of beneficial owners, screening against the terrorist-financing and proliferation-financing lists, the list of politically exposed persons and the FATF country list; set out the procedure for updating data within 15 working days once doubts arise and at least once every six months for high-risk customers.
Step 9. Set up detection of threshold transactions. Extract from paragraph 1 of Article 4 the items relevant to the entity’s activity: a real-estate agent watches the KZT 50,000,000 threshold on real-estate deals, a jeweller KZT 5,000,000, a lessor KZT 45,000,000, a notary the thresholds on the transactions in money and property that he or she certifies (real estate, movable property, gratuitous transfers of money). Make a test filing of Form FM-1 through the personal account.
Step 10. Set up monitoring of suspicious transactions. Implement the four grounds for mandatory scrutiny under paragraph 4 of Article 4 and codes 11–27 of Annex 2 to AFM Order No. 13; specify who takes the decision to treat a transaction as suspicious, within what time, and how the date and grounds are recorded; provide for counting two or more suspicious transactions of one customer so that suspicious activity is reported within three working days.
Step 11. Organise the daily and periodic procedures. Daily — screening against the AFM lists for freezing within 24 hours; on every report — checking the AFM notice within four hours and correcting within 24 hours; annually — the review of the internal control system and the risk-exposure assessment uploaded by 10 January; on any change in the legislation — additional training.
Step 12. Ensure record-keeping and information security. Organise five-year retention of customer files and transaction documents in a form that allows amounts and currencies to be reconstructed; limit the number of people who know that reports have been filed; record in the ICR the prohibition on tipping off customers and the procedure for telling a customer of a refusal or a freeze.
Author’s assessment: three steps cannot be left “for later”. The first is the notification of commencement of activity: without it, the activity itself is an offence under Article 463 of the CAO. The second is the responsible officer’s test: without the certificate, the ICR are non-compliant from day one. The third is registration in the personal account: without it, the entity can neither file a report nor receive an AFM compliance notice, and a notice under Article 14-1 posted in the account is deemed served whether or not the entity has logged in. For a foreign group that is simultaneously registering an LLP, opening an account and registering for tax, these steps fit naturally into a single launch plan; the ready-made UPPERSETUP company registration platform can serve as the starting point for such a plan.
The typical mistakes of SFMs are recurring breaches, each with a specific price in Article 214 of the CAO. Below are eight mistakes with an estimate of their cost for a medium-sized enterprise at the MCI of KZT 4,325.
Mistake 1. The company does not know it is an SFM. An accounting firm, a law firm supporting real-estate deals and LLP registrations, a real-estate agency or a jewellery shop operates without a notification, without ICR and without reports. Cost: Article 463 CAO — 40 MCI (KZT 173,000); part 16 of Article 214 — 345 MCI (KZT 1,492,125); part 8 — 280 MCI (KZT 1,211,000); part 13 for each missed threshold transaction — 300 MCI (KZT 1,297,500). In total, from KZT 4,173,625 on the first detection.
Mistake 2. The ICR are copied from someone else’s template and not uploaded to the personal account. The programmes ignore the entity’s own risk assessment, contain no review frequency for transactions and have not been updated for Law No. 219-VIII and the indicators of Order No. 13 in force since 1 April 2026. Cost: part 15 of Article 214 — a warning or 320 MCI (KZT 1,384,000); if detected in preventive control without a visit — a compliance notice with a period of not less than 10 working days and, if the notice is not complied with, inclusion in the list for control with a visit.
Mistake 3. A responsible officer without a certificate or without the required status. The functions are assigned to an accountant with no experience and no test, and no certificate is uploaded. Cost: part 11 of Article 214 — 210 MCI (KZT 908,250) for failure to implement the training programme, and part 15 — up to 320 MCI for non-compliant ICR; moreover, under AFM Order No. 6 the responsible officer may not take up the AML/CFT functions until the test has been passed.
Mistake 4. Threshold transactions are tracked by the fee rather than by the transaction amount. A real-estate agent reports only deals where the commission is large, a notary only cash settlements, although the KZT 50,000,000 real-estate threshold applies to the price of the property whatever the form of settlement. Cost: part 12 of Article 214 — a warning or 260 MCI (KZT 1,124,500) for a late report; part 13 — 300 MCI (KZT 1,297,500) for a failure to report; a repeat within a year — part 18, 375 MCI (KZT 1,621,875).
Mistake 5. A suspicious-transaction report is filed after execution without observing the 24 hours. The transaction is recognised as suspicious at a monthly review although the ICR set no review frequency, and the report goes out a week later. Cost: part 2 of Article 214 — a warning or 290 MCI (KZT 1,254,250); if treated as a failure to report — part 3, 330 MCI (KZT 1,427,250).
Mistake 6. The customer base is not screened against the lists daily. The terrorist-financing and extremism list has been updated, but a listed customer’s transactions continue on the third day. Cost: part 9 of Article 214 — 330 MCI (KZT 1,427,250) with no warning option; on repeat — 375 MCI.
Mistake 7. The customer is told the reason for a refusal by reference to a report to the AFM. An employee tells the customer that the transaction “has gone to financial monitoring for checking” or forwards an AFM request. Cost: part 17 of Article 214 — 330 MCI (KZT 1,427,250); the Law allows the customer to be told only the bare fact of a refusal, a termination or a freeze.
Mistake 8. An AFM request goes unanswered because the responsible officer is on leave. The request arrives through the personal account, the three-day deadline is missed, no extension is sought, and no stand-in — which paragraph 5 of AFM Requirements No. 4 requires the ICR to provide for during leave — has been appointed. Cost: part 4 of Article 214 — a warning or 280 MCI (KZT 1,211,000); if nothing is provided — part 5, 300 MCI (KZT 1,297,500). A written application for an extension, filed in time, generally removes the risk: the AFM may extend the three-day deadline by up to 10 working days.
Author’s assessment: seven of the eight mistakes are organisational, not legal. They arise not from the complexity of the Law but from the AML/CFT function not being embedded in the daily operating cycle: no calendar of deadlines, no deputy for the responsible officer, no mapping of thresholds to the company’s products. That is why the first AFM inspection usually finds several offences at once, and the aggregate fine for a medium-sized enterprise exceeds KZT 4,000,000 before any repeat is counted. Companies that already outsource their statutory audit and annual reporting can sensibly add the annual AML/CFT internal-control review to the same arrangement; the audit and reporting deadlines are described in Mandatory Audit and Financial Reporting in Kazakhstan in 2026.
The AML/CFT burden is distributed unevenly across the categories of SFM: the Law is the same for all, but the volume of transactions, the presence of a sector regulator and the degree of automation determine what compliance costs. Below are four typical profiles.
Banks, insurers and professional securities-market participants. For them the ICR requirements are set by the ARDFM and the National Bank, the same regulators supervise them, and reports are generated by automated systems; the burden lies in constantly updating those systems for new indicators and typologies, in remote identification and in correspondent relationships (Article 9). According to the Concept for the Development of Financial Monitoring, over 2019–2021 the financial sector filed 99 % of all reports to the AFM, and it is the sector at which the measures of Government Resolution No. 934 on “drops” and cash-outs are aimed.
Notaries, legal consultants, accounting and audit firms. Status arises from the professional activity itself; notaries work under the supervision of the Ministry of Justice pursuant to Order No. 705, lawyers and accountants under the direct supervision of the AFM pursuant to Order No. 4 and its preventive control without a visit. The burden lies in manually detecting threshold deals in real estate, participatory interests and property, in checking against the register of beneficial owners, and in the prohibition on tipping off, which runs against the professional habit of explaining every step to the client. This is the profile with the highest risk at the first inspection.
Real-estate agents, jewellers, unlicensed lessors. Here the notification of commencement of activity is added, and the thresholds — KZT 50,000,000 for real estate, KZT 5,000,000 for jewellery, KZT 45,000,000 for leasing — are triggered regularly; pawnshops, which are on the list as organisations carrying on microfinance activity (sub-paragraph 11)) with a KZT 3,000,000 threshold under sub-paragraph 1-1) of paragraph 1 of Article 4, have a similar profile. It is for this sector that the AFM, under Resolution No. 934, is preparing methodological guidance on tracking market prices of real estate and on comparing customers’ income with their spending on jewellery and precious items, and the retained “partially compliant” rating on FATF Recommendation 28 means tighter supervision.
Digital-asset operators and issuers. Since 1 May 2026 five categories of operators have been SFMs; the ICR requirements for them are set by the National Bank and the ARDFM, the thresholds for transactions in unsecured digital assets are KZT 5,000,000 and for digital financial assets KZT 7,000,000 and KZT 45,000,000, and on AFM request clients’ IP addresses and device and wallet data must be provided (Annex 7 to the Rules approved by Order No. 13). For this sector the key exposure is indicator code 16 and the forthcoming register of high-risk crypto-wallets.
How to distribute the burden. The Law allows three routes, but not all of them are open to every SFM: entrusting due diligence to another person under a contract, with responsibility remaining with the SFM (paragraph 8 of Article 5), is available to all; reliance on due diligence performed by another SFM or a foreign financial institution (paragraph 6 of Article 5) and single ICR for a financial group (paragraph 3 of Article 11) are available only to financial-sector entities under sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3. The role of responsible officer, approval of the ICR and signature of Form FM-1 cannot be outsourced — these are functions of the entity itself. A practical model for a medium-sized non-financial SFM is a responsible officer from among the managers on the payroll, holding the certificate; external methodological support for the ICR and the annual review; and in-house daily screening against the lists. Foreign-owned companies for which Kazakhstan is one of several jurisdictions can build a single customer- and beneficial-owner verification standard for all the countries where they operate: the UPPERSETUP team supports such companies through its Kazakhstan company management practice — from incorporation and tax registration to the organisation of internal control.
Author’s assessment: SFM status is no reason to abandon a line of business, but it is a reason to price the cost of compliance in advance. For a real-estate agency or a law firm the annual cost of compliance is the responsible officer’s time, the annual internal-control review and the updating of the ICR; by comparison, a single first breach under three typical offences costs a medium-sized enterprise more than KZT 4,000,000. The economically sound choice in 2026 is to embed the AML/CFT function before the first threshold transaction, not after the first compliance notice.
Who is a subject of financial monitoring in Kazakhstan?
Subjects of financial monitoring are listed in paragraph 1 of Article 3 of Law No. 191-IV: banks and organisations carrying out certain banking operations, exchanges and clearing organisations, insurers, pension funds, professional securities-market participants, notaries, advocates and legal consultants when supporting certain transactions, accounting and audit organisations, gambling operators, postal money-transfer operators, microfinance organisations, payment organisations, unlicensed lessors, dealers in precious metals and jewellery, real-estate agents, the Social Health Insurance Fund, AIFC participants, the State Corporation, mobile operators and, since 1 May 2026, five categories of digital-asset operators and issuers. State bodies are not SFMs.
Must an accounting company or a law firm report to the AFM?
Yes, if it falls within sub-paragraphs 7) or 8) of paragraph 1 of Article 3. Accounting organisations and professional accountants in private practice, as well as audit organisations, are SFMs by virtue of their activity; legal consultants and other independent specialists are SFMs only when they act for a client in real-estate transactions, the management of money, securities and accounts, the accumulation of funds for companies, and the creation, purchase, sale and management of legal entities. Information obtained while representing a client in court or before investigative bodies, or while advising, is not reported (paragraph 3 of Article 10).
What transaction amounts are subject to financial monitoring in Kazakhstan?
The thresholds of paragraph 1 of Article 4 of Law No. 191-IV in 2026: KZT 1,000,000 — winnings and cultural valuables; 3,000,000 — pawnshop transactions; 5,000,000 — jewellery, offshore counterparties, anonymous accounts, digital assets; 7,000,000 — gratuitous transfers, shares and units; 10,000,000 — currency exchange, cash transactions on accounts, transactions of companies less than three months old; 45,000,000 — leasing, bonds; 50,000,000 — real estate, movable property, precious metals, loans under National Fund programmes; 100,000,000 in equivalent — cross-border transfers in foreign currency; 500,000,000 — commodity-exchange transactions. Suspicious transactions are reported with no threshold.
By when must a threshold or suspicious transaction be reported to the AFM?
A threshold transaction — no later than the working day following the day it is carried out (paragraph 2 of Article 10). A suspicious transaction — before it is carried out, or, if it is recognised as suspicious afterwards, within 24 hours of recognition (paragraph 2 of Article 13). A customer’s suspicious activity (two or more suspicious transactions) — no later than three working days (Article 10-1). A refusal of a customer and a freeze — no later than the next working day; an answer to an AFM request — within three working days, and for a request within the analysis of a suspicious transaction — no later than the working day on which it is received. The AFM confirms acceptance of a report within four hours; a rejected report is corrected within 24 hours.
What is the personal account of a subject of financial monitoring, and is registration mandatory?
The personal account is the SFM’s profile on the AFM portal, through which reports on Form FM-1 and documents in answer to requests are filed, and to which the ICR, the risk-assessment results and the test certificate are uploaded (sub-paragraph 3-4) of Article 1; paragraph 2-1 of Article 10). Registration is mandatory for all SFMs whether or not they have reportable transactions; the procedure is set by AFM Order No. 18 of 8 December 2025. Registration is by IIN or BIN with an automatic check of the type of activity; on a mismatch, documents are sent within three working days and the AFM decides within the same period.
Who may be the AML/CFT responsible officer, and is a certificate required?
Under paragraph 3 of Article 11 the responsible officer is appointed from among senior managers or heads of units not below the head of a structural unit and must have an impeccable business reputation. For the non-financial sector, AFM Order No. 4 also requires an employment contract, reporting to the head, professional education and at least two years’ experience. The certificate is mandatory: the test is taken on the AFM website under biometric control before taking up the function (sole practitioners — within three months), consists of 100 questions in 100 minutes with a pass mark of at least 70; the result is valid for three years, and the test may be retaken after 14 calendar days.
How long must due-diligence and transaction records be kept?
At least five years: due-diligence documents, including the customer file, account data and correspondence — from the end of the business relationship; transaction documents, including threshold and suspicious transactions, and the results of scrutiny of unusual transactions — after the transaction (paragraph 4 of Article 11). Records must allow the transaction, including amounts and currencies, to be reconstructed. A breach of the record-keeping rules is punishable under part 1 of Article 214 of the CAO by a fine of 30 to 280 MCI.
May a customer be told that a transaction has been reported to the AFM?
No. Paragraph 5 of Article 11 prohibits informing customers and other persons of the AML/CFT measures taken and of reports filed; the customer may be told only of a freeze, a refusal to establish a relationship and a refusal of a transaction. Receipt from the AFM of a list of persons carrying out suspicious transactions may not be disclosed either (paragraph 5-1). A breach is punishable under part 17 of Article 214 of the CAO by a fine of 75 to 640 MCI.
What is the fine for breaching the financial-monitoring law in 2026?
Article 214 of the CAO, in the wording in force since 2 March 2026, contains 19 offences. For a medium-sized enterprise: no ICR — 345 MCI (KZT 1,492,125); failure to take due-diligence measures — 280 MCI; failure to report a threshold transaction — 300 MCI; failure to report a suspicious transaction — 330 MCI; breach of freezing — 330 MCI; tipping off a customer — 330 MCI; a repeat within a year — 375 MCI; three or more breaches — 900 MCI with suspension of the licence for up to six months or a ban on activity for up to three years. For large business the maximum fine is 1,800 MCI (KZT 7,785,000). The 2026 MCI is KZT 4,325.
What changed in the AML/CFT law in 2025–2026?
Law No. 219-VIII of 19 September 2025 (in force since 20 November 2025) renamed the Law, introduced reporting of a customer’s suspicious activity (Article 10-1) and AFM preventive control without a visit (Article 14-1), and rewrote Article 11-1 on risk assessment. AFM Order No. 13 has contained updated suspicion indicators with codes 11–27 since 1 April 2026. Law No. 259-VIII of 16 January 2026 added digital-asset operators and issuers to the SFM list from 1 May 2026. Article 214 of the CAO has applied in its new wording since 2 March 2026. Law No. 311-VIII of 12 June 2026 refined the politically exposed person criterion from 13 August 2026.
Must an ordinary LLP that is not an SFM identify its own beneficial owners?
Yes. Under Article 12-3 of Law No. 191-IV every legal entity and foreign structure without legal personality must identify its beneficial owners on the AFM form, verify and update the information at least once a year, keep it for five years and provide it to the AFM on request; founders and controlling persons must supply the company with the data. Failure to provide the information on request is punishable under part 7 of Article 214 of the CAO by a fine of 45 to 420 MCI.
Is Kazakhstan on the FATF “grey list”?
No. Kazakhstan is not on the FATF list of jurisdictions under increased monitoring of 19 June 2026 (22 jurisdictions). Kazakhstan is assessed within the Eurasian Group (EAG): the third-round report was adopted on 8 June 2023, and the first follow-up report, adopted in May 2026, upgraded the ratings on Recommendations 6, 7, 24 and 26; the country is rated “compliant” or “largely compliant” on 37 of the 40 Recommendations and remains in regular follow-up.
First. SFM status arises automatically from carrying on an activity on the 27-item list in paragraph 1 of Article 3 of Law No. 191-IV, including notaries, legal consultants, accounting and audit firms, real-estate agents, jewellers, lessors and, since 1 May 2026, digital-asset operators and issuers; legal consultants (but not advocates), lessors, jewellers and real-estate agents additionally file a notification of commencement of activity under Law No. 202-V.
Second. Kazakhstan’s regime is dual-track: reports are required both for threshold transactions at fixed amounts from KZT 1,000,000 to KZT 500,000,000 (no later than the next working day) and for suspicious transactions with no threshold (before execution or within 24 hours of recognition), and, since 20 November 2025, for a customer’s suspicious activity of two or more transactions (three working days).
Third. Due diligence under Article 5 comprises seven measures — from identification by IIN and BIN to ongoing monitoring — with a mandatory check of the beneficial owner against the state register, updating of data within 15 working days once doubts arise, enhanced due diligence for politically exposed persons and customers from FATF-listed jurisdictions, and exemptions for one-off transactions of up to KZT 500,000.
Fourth. Internal control rests on ICR made up of at least five programmes, a responsible officer at the level of head of unit, holding an AFM certificate (a 100-question test, valid for three years), an annual review of the control system and a risk assessment uploaded to the personal account by 10 January; registration in the personal account is mandatory for every SFM.
Fifth. Transactions of persons on the AFM lists are frozen within 24 hours, the AFM’s decision on a suspicious transaction is taken within 24 hours with suspension for up to three working days, law-enforcement bodies decide within 72 hours, and debit transactions may be suspended for up to 15 calendar days; refusal of a customer where due diligence is impossible is mandatory, and the confidentiality of reports is protected by the prohibition on tipping off.
Sixth. Article 214 of the CAO, in the wording in force since 2 March 2026, contains 19 offences with fines from 30 to 1,800 MCI (KZT 129,750 to KZT 7,785,000 at the MCI of KZT 4,325), with suspension of the licence or a ban on activity for up to three years for a third breach within a year; a legal entity is liable under Article 214-1 for up to 2,000 MCI, and individuals under Article 218 of the Criminal Code for up to 10 years’ imprisonment with confiscation.
Seventh. Supervision is shifting to the non-financial sector: the AFM has acquired preventive control without a visit (Article 14-1), Kazakhstan’s rating on FATF Recommendation 28 on the supervision of non-financial entities remained “partially compliant” in the EAG report of May 2026, and Government Resolution No. 934 provides for new suspicion indicators and methodological guidance for real-estate agents and jewellers during 2026.
A subject of financial monitoring in Kazakhstan is a person on the list in paragraph 1 of Article 3 of Law No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction”: banks, insurers, professional securities-market participants, notaries, advocates and legal consultants when supporting transactions, accounting and audit firms, gambling operators, microfinance and payment organisations, unlicensed lessors, jewellers, real-estate agents, mobile operators, AIFC participants and, since 1 May 2026, digital-asset operators and issuers. The duties are: to register in the AFM personal account (and, for legal consultants, lessors, jewellers and real-estate agents, to file a notification of commencement of activity); to conduct due diligence on customers and beneficial owners, updating the data within 15 working days once doubts arise; to report threshold transactions from KZT 1,000,000 to KZT 500,000,000 no later than the next working day, suspicious transactions before execution or within 24 hours of recognition, and suspicious activity within three working days, on Form FM-1; to adopt internal control rules made up of at least five programmes, appoint a responsible officer holding an AFM certificate (a 100-question test, valid for three years), and review the control system and assess risks annually; to freeze transactions of listed persons within 24 hours; to refuse customers where due diligence is impossible; and to keep records for five years without tipping off customers. Liability: Article 214 of the Code of Administrative Offences (since 2 March 2026) — 19 offences with fines from 30 to 1,800 MCI (the 2026 MCI is KZT 4,325), and for a third breach within a year suspension of the licence for up to six months or a ban on activity for up to three years; Article 214-1 — up to 2,000 MCI for legal entities; Article 218 of the Criminal Code — up to 10 years’ imprisonment. Key changes: Law No. 219-VIII (since 20 November 2025) introduced suspicious activity and AFM preventive control without a visit; AFM Order No. 13 updated the suspicion indicators (codes 11–27) from 1 April 2026; Law No. 259-VIII added digital-asset operators from 1 May 2026. Kazakhstan is not on the FATF increased-monitoring list of June 2026 and is rated “compliant” or “largely compliant” on 37 of the 40 Recommendations in the EAG report of May 2026.
Laws and codes of the Republic of Kazakhstan (Adilet legal information system, consolidated texts)
2. Law No. 219-VIII of 19 September 2025 — amendments on AML/CFT/CPF
4. Law No. 256-VIII of 9 January 2026 — amendments on digitalisation, transport and entrepreneurship
5. Law No. 311-VIII of 12 June 2026 — amendments on combating corruption
7. Law No. 23-VIII of 12 July 2023 — return of illegally acquired assets to the state
8. Law No. 131-VII of 1 July 2022 — amendments on AML/CFT and state price regulation
9. Law No. 73-VII of 18 November 2021 — amendments on AML/CFT
10. Law No. 325-VI of 13 May 2020 — amendments on AML/CFT
11. Code of Administrative Offences No. 235-V of 5 July 2014 — Articles 214, 214-1, 463
13. Criminal Code No. 226-V of 3 July 2014 — Articles 218, 218-1
14. Law No. 202-V of 16 May 2014 “On Permits and Notifications” — Annex 3, item 35
AFM orders and acts of sector regulators
20. AFM Order No. 18 of 8 December 2025 — Rules for the Personal Account
23. Order of the Minister of Justice No. 705 of 28 November 2025 — ICR requirements for notaries
Acts of the President and the Government, official statements
31. AFSA — Relevance of amendments to Kazakhstan’s AML/CTF law to AIFC Participants (2020 amendments)
FATF and EAG
32. FATF — Jurisdictions under Increased Monitoring, 19 June 2026
33. EAG — On publication of the 1st Follow-up Report of the Republic of Kazakhstan, 29 June 2026
34. EAG — 1st Regular Follow-up Report of the Republic of Kazakhstan (PDF)
35. EAG — Outcomes of the 44th EAG Plenary meeting, Ashgabat, 19–23 May 2026
36. FATF — Mutual Evaluation Report of the Republic of Kazakhstan, 2023 (PDF)
UPPERSETUP materials
37. Permits and Notifications in Kazakhstan in 2026
38. Digital Assets and Mining in Kazakhstan 2026
39. LLP (TOO) in Kazakhstan for Foreigners 2026
40. Opening a Bank Account in Kazakhstan for a Foreign Company and a Non-Resident
41. Currency Control in Kazakhstan 2026
42. AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026
43. The UAE UBO Register and goAML
44. Kazakhstan + UAE: The Dual Structure in 2026
45. DNFBP AML Compliance in the UAE 2026
46. Bankruptcy and Rehabilitation of Legal Entities in Kazakhstan in 2026
47. Mandatory Audit and Financial Reporting in Kazakhstan in 2026
48. Personal Data and Localisation in Kazakhstan in 2026
49. The Hong Kong TCSP Licence in 2026
A note on sources. All provisions of Law No. 191-IV, the Code of Administrative Offences, the Criminal Code, Law No. 202-V and the subordinate acts are cited from the consolidated texts of the Ministry of Justice’s Adilet legal information system, read on 10 September 2026; the commencement dates of amendments are calculated from the first-official-publication dates given in the acts’ record cards and cross-checked against the notes in the Paragraph information system. Fines are converted into tenge at the 2026 MCI of KZT 4,325. AFM statistics for 2025 are taken from the official Akorda.kz statement; the figures on the number of SFMs and reports from the Concept for the Development of Financial Monitoring; the results of the international assessment from EAG and FATF publications. Law No. 191-IV contains no list of offshore zones for the threshold transaction under sub-paragraph 2) of paragraph 1 of Article 4: the dedicated Ministry of Finance list of 2010 was repealed with effect from 15 November 2020, and the list to be applied should be fixed in the ICR in the light of AFM guidance. Local boutique consulting and company-formation firms and aggregators were not used as sources. All links were checked on 10 September 2026.
This material is for information purposes only and does not constitute legal, tax, financial, investment or consulting advice. Before taking any decision, individual professional advice should be obtained that takes into account the specific situation, the jurisdiction, the status of the company and the current requirements of the regulators.
Current as of September 2026.
Everything you need to start and run a business - in one place
Kazakhstan company with a complete set of incorporation documents
Accounting and Tax Compliance, Reporting, and Support in Accordance with Kazakhstan Requirements
Visas, Work Permits
Corporate Bank Accounts in Kazakhstan and Payment Services
Business Licenses and Activity Permits
Corporate Documents, Contracts, Compliance, Licensing, and Company Structure Changes